ActiveCollab before 2.3.2 allows remote authenticated users to bypass intended access restrictions, and (1) delete an attachment or (2) subscribe to an object, via a crafted URL.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Activecollab |
Activecollab |
* |
2.3.1 (including) |
References